1. Who we are
For the purpose of this Privacy Policy, the data controller is:
Semly Pro, a sole proprietorship (eenmanszaak) established in the Netherlands, trading as “SemlyPro” (“we”, “us”, “our”).
- Registered address: Hawaiiweg 41, 1339 NW Almere, Netherlands
- KvK (Dutch Chamber of Commerce) number: 99448351
- VAT ID: NL005387029B31
- Owner (sole proprietor): Surya Pillai
- General contact: anil@semlypro.com
- Privacy contact: anil@semlypro.com
- Security contact: anil@semlypro.com
- Legal notices: anil@semlypro.com
- India Grievance Officer: anil@semlypro.com (see Section 17)
SemlyPro currently operates as a Dutch sole proprietorship. This means the owner(s) named above are the natural person(s) legally responsible as controller, and there is at present no separate legal entity (“Semly Pro B.V.”) in existence. We intend to incorporate a private limited company, Semly Pro B.V. Upon incorporation, the controller function under this Policy will transfer to Semly Pro B.V., we will update this Policy, and references to “SemlyPro” will be read as references to Semly Pro B.V. Until then, the current entity above is the controller.
1.1 United Kingdom — Article 27 representative and ICO registration
If you are in the United Kingdom, we act as the controller of your personal data under the UK GDPR. Because we are established in the Netherlands with no establishment in the United Kingdom, and we offer services to and monitor individuals in the UK on more than an occasional basis, we are required to designate a UK representative under Article 27 UK GDPR. We are appointing a UK representative for this purpose and will publish the representative’s name and UK postal address here.
You may contact our UK representative on any matter relating to our processing of your personal data, in addition to contacting us directly at anil@semlypro.com.
We have registered (or will register before launch) with the Information Commissioner’s Office (ICO) and pay the annual data protection fee under the Data Protection (Charges and Information) Regulations 2018. The applicable fee tier is self-assessed by reference to our size and turnover (currently £52 for tier 1, £78 for tier 2, and £3,763 for tier 3).
1.2 Data Protection Officer
We have not appointed a Data Protection Officer, as we are not currently required to do so under Article 37 GDPR (our core activities do not consist of large-scale processing of special-category data or large-scale, regular and systematic monitoring in a manner triggering a mandatory appointment). We will review this position as our processing activities scale. Note that under India’s DPDP Act, if we are designated a Significant Data Fiduciary, we will appoint an India-based Data Protection Officer at that time (see Section 17).
2. Scope of this Policy
This Privacy Policy explains how we collect, use, share, and protect personal data when you:
- Visit semlypro.com, semlypro.nl, app.semlypro.com, or any subdomain we operate;
- Create an account or use the SemlyPro Service, including our free SEO tools on the marketing site;
- Use our Model Context Protocol (MCP) server (for example from Claude Desktop or Claude Code) or any browser extension or plugin we make available;
- Interact with us by email, chat, phone, or on social media;
- Subscribe to our newsletter or attend an event we host;
- Apply for a job with SemlyPro.
This Policy does not apply to third-party websites, services, or platforms linked from or integrated with the Service. Their privacy practices are governed by their own policies.
Where you upload or connect personal data of third parties to the Service (for example, contact data of your customers, competitor contact data, spreadsheet uploads, or data ingested from your connected Google Ads, Google Analytics or Search Console accounts for content-personalisation or analysis purposes), you are the controller (or, for Indian Data Principals, the Data Fiduciary) of that data and SemlyPro acts as your processor (or Data Processor). Our processing on your behalf is governed by our Data Processing Agreement (DPA), available at semlypro.com/dpa.
3. Personal data we collect
3.1 Data you provide directly
- Account data. Name, work email address, company name, role, country, password (stored as a salted hash), profile picture (optional).
- Billing data. Billing address, VAT number, tax ID, and payment method. Payment card details are collected and stored by our payment processor (Stripe); we do not store card numbers on our systems.
- Customer Materials. Keywords, briefs, brand information, competitor URLs, sample content, publishing credentials for Third-Party Services, and any other content you submit to the Service. This expressly includes files you upload — such as Excel/CSV/spreadsheet files — which may contain arbitrary tabular data, including contact lists, names, and email addresses. Customer Materials may contain personal data of third parties, in which case you act as controller/Data Fiduciary and SemlyPro acts as processor/Data Processor under the DPA. Please do not upload special-category data (see Section 3.4).
- Communications. Content of emails, support tickets, chat messages, feedback, and survey responses.
- KYC and verification data (higher tiers). For Managed-plan and enterprise Customers, we may collect business-verification data, sanctions-screening results, and beneficial-ownership information.
3.2 Data we collect automatically
- Usage data. Actions you take in the Service, features used, time spent, error events, and diagnostic logs.
- Device and connection data. IP address, device type, operating system, browser, language, referrer URL, timestamp of access.
- Cookies and similar technologies. See our Cookie Policy for detail.
- Browser extensions / plugins. Where you install a SemlyPro browser extension or plugin, it may access the content and context of web pages you use it on (for example page URL, on-page SEO elements, and DOM content) strictly to provide the feature you invoke. We disclose in the relevant web-store listing exactly what the extension accesses and the justification for each requested permission. We do not sell data collected via the extension and we limit its use to providing and improving the feature, consistent with the applicable web-store developer program policies (for example the Chrome Web Store and Firefox AMO limited-use requirements).
- MCP server. Where you use our MCP server through a third-party client (for example Claude Desktop or Claude Code), that client acts as an intermediary in the data flow between you and the Service; the client’s own handling of your data is governed by its provider’s privacy policy.
3.3 Data from third parties
- OAuth-connected CMS and publishing accounts. If you connect a Third-Party Service (for example WordPress, Webflow, Shopify), we receive the credentials, tokens, and metadata that service authorises us to receive.
- Google data integrations (Google Ads, Google Analytics 4, Google Search Console). Where you authorise it via OAuth, we ingest data from your connected Google accounts to provide analysis and reporting on your instruction:
- Google Ads — campaign, spend, performance, conversion and audience data (which may include customer-list or audience personal data);
- Google Analytics 4 (GA4) — traffic, audience, session, conversion and event data (which may include IP addresses, client/user identifiers and other personal data);
- Google Search Console — search query, impression, click, position and indexing data for your verified property. This is your data, ingested on your authorised instruction; SemlyPro acts as your processor for it. SemlyPro’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to train generalised or public AI models, for advertising or retargeting, or for any purpose other than providing and improving the user-facing features you request, and we do not transfer or sell it except as necessary to provide those features, to comply with law, or as part of a merger/acquisition after you are notified. A fuller description is set out in our Google API Services / Limited Use Compliance Statement.
- Payment processor. Transaction status, invoice history, and fraud-risk signals from Stripe.
- Our own product analytics. Aggregated behavioural data about how our own Service is used, collected through the analytics tool we operate (see Section 6.1). This is distinct from any Google Analytics data you connect under the paragraph above.
- Sanctions and compliance databases. Screening results from providers we use to comply with sanctions and export-control law.
3.4 Sensitive data
We do not intentionally collect special categories of personal data (as defined in Article 9 GDPR). Please do not submit health, biometric, racial, political, religious, sexual-orientation, or trade-union data to the Service, including within uploaded files. Where you submit such data as part of Customer Materials without our request, you warrant that you have a valid Article 9 legal basis (and, for Indian Data Principals, valid consent under the DPDP Act) and that you have provided any notices your applicable law requires. We disclaim liability for the consequences of your submission of such data.
4. Purposes and legal bases for processing
We process personal data on the following legal bases under Article 6 GDPR. For Indian Data Principals, the corresponding lawful basis is consent or a “certain legitimate use” permitted by the DPDP Act, rather than “legitimate interest” — see Section 17.
| Purpose | Categories of data | Legal basis |
|---|---|---|
| Create and administer your account; provide the Service; process publishing, tracking and analysis on your behalf (including ingesting connected Google Ads/GA4/Search Console data) | Account data, Customer Materials, connected-service data | Article 6(1)(b) — necessary for performance of the contract with you |
| Process payments, invoicing, tax; retain financial records | Billing data, transaction data | Article 6(1)(b) — contract; Article 6(1)© — legal obligation (Dutch tax law) |
| Provide customer support, and troubleshoot, debug and investigate issues you report | Communications, account data, and — where necessary to reproduce or resolve the issue — Customer Materials | Article 6(1)(b) — contract; Article 6(1)(f) — legitimate interest in maintaining a working Service |
| Maintain security, prevent fraud, detect abuse (including AUP violations), enforce these Terms and the AUP | Usage data, device data, IP address | Article 6(1)(f) — legitimate interest in operating a secure and lawful service |
| Review, quality-assure and internally improve the Service and its models (analytics, feature usage, bug diagnostics, and internal, non-public evaluation and improvement) — excluding any training of publicly-released AI models | Usage data, device data, and, where used, pseudonymised or anonymised data (Customer Materials are used for this purpose only within the bounds of Section 5.2 and Section 10.1 and, for processor-side data, only as authorised by the DPA) | Article 6(1)(f) — legitimate interest, balanced against your rights, using pseudonymised or anonymised data where reasonably possible |
| Send transactional emails (billing, security alerts, service updates) | Account data, communications | Article 6(1)(b) — contract |
| Send marketing emails and newsletters | Account data, marketing preferences | Article 6(1)(a) — consent; you may withdraw at any time. For UK recipients, electronic marketing is also governed by PECR reg. 22 (see Section 4.1) |
| Screen for sanctions and export-control compliance | Account data, KYC data | Article 6(1)© — legal obligation (where applicable); Article 6(1)(f) — legitimate interest |
| Comply with other legal, tax, and regulatory obligations | All categories as required | Article 6(1)© — legal obligation |
| Establish, exercise, or defend legal claims (including AUP enforcement) | All categories as required | Article 6(1)(f) — legitimate interest |
| Recruit and evaluate job candidates | Application data | Article 6(1)(b) — pre-contractual steps; Article 6(1)(a) — consent |
Where we rely on legitimate interest, we have carried out a balancing exercise and concluded that our interests are not overridden by your rights and freedoms. You may request further information about our balancing analysis at anil@semlypro.com.
4.1 Electronic marketing (UK PECR and soft opt-in); marketing & CRM data
For recipients in the United Kingdom, direct electronic marketing is governed by the Privacy and Electronic Communications Regulations 2003 (PECR) reg. 22, in addition to the GDPR lawful basis. We obtain prior consent for marketing to individual subscribers, save where we rely on the “soft opt-in” (PECR reg. 22(3)) for existing customers of similar products who were offered an opt-out at the point of collection and in every message. Every marketing email carries our sender identity and a working one-click unsubscribe, and we action opt-outs promptly (PECR reg. 23; ePrivacy Directive Art. 13; Dutch Telecommunicatiewet). Note that under the Data (Use and Access) Act 2025, PECR marketing penalties are now aligned to UK GDPR levels.
We use a customer-relationship-management (CRM) and marketing platform to capture leads and manage communications, and we may operate audience-matching tags on our marketing site (for example LinkedIn and Google) as described in the Cookie Policy. Where we upload hashed contact data to build a marketing audience, we do so only on a documented lawful basis. We retain marketing/CRM contact records in line with Section 8 and honour opt-outs and suppression requests.
5. How we use AI in providing the Service
The Service uses large-language-model providers (currently OpenAI Ireland Limited and Anthropic PBC) to generate content and analyse search-related data.
5.1. Processing on your behalf. When you submit Customer Materials for content generation or analysis, your Customer Materials are sent to an AI Provider for processing. The AI Provider processes your data as a sub-processor on our behalf. We rely on:
- Contractual arrangements with each AI Provider that prohibit them from using your data to train their public models by default;
- Data-processing agreements that include Standard Contractual Clauses where transfers outside the EEA occur;
- Technical measures including regional routing where available.
5.2. No training on your data. SemlyPro does not use your Customer Materials or Content generated for you to train publicly-released AI models. Our contractual arrangements with each AI Provider require them not to use your data to train their public models. Any internal, non-public review or improvement of the Service is bounded by Section 10.1 and, for personal data we process on your behalf as processor, is limited to what the DPA authorises (and, wherever practicable, to pseudonymised or anonymised data). This position on public-model training may be changed only by our express written notice to you and, where required by law, with your opt-in consent.
5.3. Automated decision-making (Article 22 GDPR). Our Service produces content, audits, and recommendations that are advisory. We do not use the Service to make solely automated decisions that produce legal or similarly significant effects on data subjects (Article 22 GDPR). If you use the Service in a manner that would constitute such automated decision-making about identifiable individuals, that use is your responsibility and you must comply with Article 22 in your own capacity.
5.4. EU AI Act transparency. In connection with Article 50 of the EU AI Act, we disclose to you that Content produced by the Service is generated with the substantial assistance of AI. Where you publish that Content in contexts subject to Article 50 or equivalent disclosure obligations, you are responsible for making the disclosure required by that law to your end-users.
5.5. EU AI Act classification. For the purposes of the EU AI Act (Regulation (EU) 2024/1689):
- SemlyPro deploys AI systems that are built on general-purpose AI models supplied by our AI Providers (that is, SemlyPro is a deployer of those AI systems).
- SemlyPro may be a provider of a downstream AI system in respect of Content generation and analysis features SemlyPro places on the market under its own brand (Article 25 EU AI Act).
- You (the Customer) are a deployer of the Service in your own capacity when you use it, and may in turn be a provider under Article 25 if you rebrand or resell SemlyPro Content under your own brand.
5.6. Article 50 content marking. From 2 August 2026, SemlyPro will mark AI-generated Content in a machine-readable format detectable as artificially generated or manipulated, using technical solutions that are effective, interoperable, robust, and reliable insofar as this is technically feasible, in accordance with Article 50(2) EU AI Act. Details will be described at semlypro.com/ai-transparency. We will keep this text aligned with any transitional period adopted under the EU AI Act (for example any deferral applicable to systems already on the market before 2 August 2026).
5.7. Serious-incident reporting (Article 73 EU AI Act). To the extent the Service constitutes a high-risk AI system within the meaning of the EU AI Act (which we do not currently consider it to be), from 2 August 2026 we will report serious incidents involving the Service to the competent market surveillance authority in accordance with Article 73 EU AI Act, within the statutory time frames (15 days standard; 2 days for widespread infringement; 10 days for death cases). You are required to notify us of serious incidents you become aware of; the process is described in the Terms of Service (clause 8A.5).
5.8. Prohibited practices and high-risk uses. We prohibit use of the Service for practices prohibited by Article 5 EU AI Act and for the high-risk use categories in Annex III EU AI Act, save with our prior written consent. See our Acceptable Use Policy for detail.
6. Who we share your personal data with
We share personal data with the following categories of recipients, only to the extent necessary and under written contracts that require them to protect your data. A current, complete and authoritative list of sub-processors is maintained at semlypro.com/subprocessors; the list below is a summary and, in case of any difference, the /subprocessors page prevails.
6.1 Service providers acting as our processors
- Vercel Inc. — cloud hosting and application delivery; EU region (Amsterdam / Frankfurt) for personal data of EU customers.
- Cloudflare, Inc. — DNS, DDoS protection, and edge/network security.
- Amazon Web Services EMEA SARL (or equivalent EU cloud infrastructure provider) — infrastructure services; EU region.
- Stripe Payments Europe, Limited — payment processing.
- OpenAI Ireland Limited — AI content generation.
- Anthropic PBC — AI content generation and analysis. (Note: Anthropic PBC is a US contracting entity; see the transfer analysis in Section 7.)
- Postmark or Resend — transactional email.
- HubSpot or Customer.io — marketing email and CRM (only where you have consented or the soft opt-in applies).
- Intercom or Crisp — customer support and chat.
- Sentry — error monitoring.
- PostHog or Plausible — product analytics.
- Onfido or Sumsub — sanctions screening for higher-tier accounts.
We will notify Customers of new sub-processors with reasonable advance notice, and you may object on legitimate grounds under the DPA (the objection window runs from the date the /subprocessors list is updated).
6.2 Third-Party Services you authorise
When you connect a Third-Party Service to the Service (for example a CMS, or your Google Ads / Google Analytics / Search Console accounts), we exchange the personal data necessary to perform the connection you have authorised. That third party (for example Google Ireland Limited / Google LLC) processes your data under its own privacy policy, as an independent controller for its own purposes; SemlyPro’s handling of the data it returns to us is described in Sections 3.3 and 5 and, where we process it on your behalf, in the DPA.
6.3 Legal recipients
We may disclose personal data if required by law, by a valid legal request from a competent authority, or where we determine in good faith that disclosure is necessary to (a) comply with a legal obligation, (b) protect the rights, property, or safety of SemlyPro, our customers, or the public, © enforce our Terms, the AUP, or the DPA, or (d) prevent or investigate suspected fraud, security incidents, or violations of the AUP.
6.4 Corporate transactions
If SemlyPro is involved in a merger, acquisition, financing, or asset transfer — including the incorporation of Semly Pro B.V. and the transfer of the business to it — personal data may be transferred as part of that transaction. We will notify you in advance of any such transfer that changes how your personal data is processed.
7. International transfers
Some of our sub-processors are located outside the European Economic Area, including in the United States. We apply different safeguards depending on the origin of the data:
7.1 EEA-origin personal data → third countries. When we transfer EEA personal data outside the EEA, we rely under Chapter V GDPR on:
- Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914); and/or
- The EU–US Data Privacy Framework where the recipient is certified. (The EU–US Data Privacy Framework remains valid but is subject to a pending appeal before the Court of Justice of the EU, Case C-703/25 P; we therefore keep Standard Contractual Clauses in place as a fallback safeguard.)
7.2 UK-origin personal data → third countries. For UK personal data transferred outside the UK, we rely on:
- The UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs; and/or
- The UK Extension to the EU–US Data Privacy Framework (the “UK–US data bridge”, in effect since 12 October 2023) for certified US importers.
We do not treat the EU’s adequacy decision for the United Kingdom as an outbound transfer safeguard: that decision governs inbound EEA→UK flows and was renewed by the European Commission on 19 December 2025, running to 27 December 2031. The Sub-processor List identifies the transfer mechanism relied on for each recipient.
7.3 India-origin personal data. For personal data of Indian Data Principals, cross-border transfer is addressed in Section 17.
You can request a copy of the safeguards in place for a particular transfer by contacting anil@semlypro.com.
8. Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. Our retention scheme is consistent across the Terms of Service (clause 18), the DPA (clause 12) and any Enterprise Master Services Agreement (MSA):
- Account and Customer Materials. For the duration of your subscription and for a post-termination export window — thirty (30) days for standard plans, or ninety (90) days where an Enterprise agreement/MSA so provides — to allow account restoration or export. Longer if required by law or if termination was for cause (see Terms clause 18).
- Backups. Residual copies in backups are purged within ninety (90) days.
- Billing and tax records. For seven (7) years, in accordance with Dutch tax law.
- Support communications. For up to three (3) years from the date of the communication.
- Marketing consents and preferences. Until you withdraw consent or object; unsubscribe/suppression records are retained to honour your preference.
- Security logs. For up to twelve (12) months.
- Data processed for legal-claim defence or AUP enforcement. Until claims are time-barred under applicable law.
- KYC and sanctions-screening records. For seven (7) years where a legal obligation to retain them applies; where no such statutory obligation applies to us, we retain them on the basis of our legitimate interest in demonstrating sanctions/export-control compliance.
After the applicable retention period, we delete or anonymise personal data.
9. Your rights under GDPR and UK GDPR
You have the following rights in relation to personal data we hold about you:
- Right of access (Article 15) — obtain a copy of your personal data and information about how we process it.
- Right to rectification (Article 16) — correct inaccurate or incomplete personal data.
- Right to erasure (Article 17) — request deletion of personal data where the legal grounds for retaining it no longer apply.
- Right to restriction (Article 18) — limit our processing of your personal data in certain circumstances.
- Right to data portability (Article 20) — receive personal data you provided in a structured, commonly used, machine-readable format.
- Right to object (Article 21) — object to processing based on legitimate interest, including profiling; object to processing for direct marketing at any time.
- Right to withdraw consent (Article 7(3)) — withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
- Right not to be subject to solely automated decisions producing legal or similarly significant effects (Article 22).
- Right to lodge a complaint with a supervisory authority. In the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). In the UK, it is the Information Commissioner’s Office (ico.org.uk). Data Principals in India may raise a grievance and, if unresolved, complain to the Data Protection Board of India (see Section 17).
To exercise any of these rights, contact anil@semlypro.com. We will respond within one month of receiving your request, unless the request is complex or numerous, in which case we may extend the period by up to two additional months and will inform you of the extension. We may need to verify your identity before responding.
Where you are exercising rights in respect of personal data that we process on behalf of one of our Customers (that is, where you are a data subject of Customer Materials), we will forward your request to the relevant Customer and support their response as required by the DPA. You should contact that Customer directly where possible.
9.1 Internal complaints procedure
If you are unhappy with how we have handled your personal data, you may complain to us directly at anil@semlypro.com before (or instead of) approaching a supervisory authority. In line with the UK Data (Use and Access) Act 2025 (in force from 19 June 2026), we will acknowledge your data-protection complaint within 30 days of receiving it and respond without undue delay. This internal route does not affect your right to complain to a supervisory authority at any time.
10. How we secure your personal data
We implement technical and organisational measures appropriate to the risk, including:
- Encryption in transit (TLS 1.2 or higher) and at rest for sensitive data.
- Access controls with role-based permissions and multi-factor authentication for administrative access.
- Regular security review, dependency scanning, and vulnerability patching.
- Isolation of production and non-production environments.
- Backups with time-limited retention.
- Employee and contractor training on data protection, and access to personal data on a need-to-know basis.
- Incident-response processes designed to detect, contain, and notify affected parties as required by Articles 33 and 34 GDPR (and the DPDP Act where Indian Data Principals are affected — see Section 11).
- Coordinated vulnerability disclosure at anil@semlypro.com.
No system is completely secure. If you have reason to believe your account or data has been compromised, contact anil@semlypro.com immediately.
10.1 Personnel and contractor access to Customer Materials and Content
SemlyPro personnel and authorised contractors may access Customer Materials and Content only as necessary to (a) provide, maintain and secure the Service; (b) troubleshoot, debug and provide support; © investigate abuse, security or Acceptable Use Policy issues; and (d) review and improve the Service and its models for SemlyPro’s internal, non-public purposes only. Such access is subject to confidentiality obligations, least-privilege / role-based access controls, and access logging. SemlyPro does not use Customer Materials or Content to train publicly-released AI models (see Section 5.2). Where we process Customer Materials as your processor, this access is exercised only within the documented instructions and safeguards of the DPA. Our internal Staff Data-Access Policy operationalises these controls.
11. Data breach notification
Where we become aware of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will:
- Notify the relevant supervisory authority (Autoriteit Persoonsgegevens or other competent authority) without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with Article 33 GDPR;
- Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms, in accordance with Article 34 GDPR;
- Where you are our Customer and personal data you have entrusted to us as processor is affected, notify you in accordance with the DPA so you can meet your own controller notification obligations.
India (DPDP Act). Where a personal data breach affects the personal data of Indian Data Principals and we are the Data Fiduciary, we will (in addition to the above, and following the DPDP Rules 2025) give the Data Protection Board of India an initial intimation without delay, followed by a detailed report within 72 hours (or such longer period as the Board allows), and will notify each affected Data Principal directly, in plain language, describing the nature of the breach, the data affected, mitigation measures, and our contact details. See Section 17.
Notifying is not an admission of liability.
12. Data Processing Agreement for Customers
Where you use the Service to process personal data of third parties (for example your end-customers), you are the data controller (or Data Fiduciary) and SemlyPro acts as your data processor (or Data Processor). Article 28 GDPR requires a written data processing agreement between you and SemlyPro; the DPDP Act similarly requires processing by a Data Processor to be under a valid contract.
Our standard Data Processing Agreement is available at semlypro.com/dpa. It is deemed accepted and takes effect automatically when you upload or connect personal data of third parties to the Service, unless we sign a bespoke DPA with you. The retention and deletion windows referenced in the DPA are those set out in Section 8 and in your applicable Terms or Master Services Agreement.
13. Notice-and-action for illegal content (Digital Services Act)
Under Article 16 of the Digital Services Act (Regulation (EU) 2022/2065), any person may notify us of Content hosted on our systems that they consider illegal. To submit a notice, contact anil@semlypro.com with:
- a sufficiently detailed explanation of why you consider the content illegal;
- the URL or identifier of the content;
- your name and contact details (except where the content relates to Articles 3 to 7 of Directive 2011/93/EU on the sexual abuse of children); and
- a statement confirming your good-faith belief that the information provided is accurate and complete.
We will process notices without undue delay and will inform you of our decision and of any redress available. For content connected to Indian users, our India Grievance Officer route (Section 17) and our IP & Illegal Content Takedown Policy also apply.
14. Cookies and similar technologies
We use cookies and similar technologies to operate, secure, and improve the Service. Full detail is in our Cookie Policy. Where required by law, we obtain your consent before setting non-essential cookies, and you can adjust your preferences at any time through our cookie banner. Cookie consent for UK visitors is governed by PECR reg. 6 (in addition to the ePrivacy Directive Art. 5(3) and the Dutch Telecommunicatiewet).
15. Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal data from children. As a global floor we treat individuals under 16 as children (the Dutch/GDPR digital-consent age; the UK information-society-services age is 13, so this floor is more protective in the UK). For India, a “child” is anyone under 18 (see Section 17): we do not knowingly process the personal data of an Indian user under 18 without verifiable parental/guardian consent, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe we have collected a child’s data, contact anil@semlypro.com and we will delete it promptly.
16. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be notified by email or in-product notice at least thirty (30) days before they take effect. The “Last updated” date at the top of this Policy shows when it was most recently revised.
17. India-specific provisions (Digital Personal Data Protection Act 2023)
This Section applies to Data Principals in India and to our processing of their personal data. It supplements the rest of this Policy; where this Section conflicts with another section in respect of Indian Data Principals, this Section prevails. India’s Digital Personal Data Protection Act 2023 (DPDP Act) has extraterritorial effect over the offering of goods or services to Data Principals in India. The DPDP Rules 2025 were notified on 14 November 2025 and are being phased in, with the substantive Data Fiduciary obligations (itemised notice and consent, Data Principal rights, security safeguards, children’s data, breach reporting and cross-border transfer) operative from 14 May 2027. We are building toward full compliance ahead of that date, and the grievance and contact provisions below are available now.
17.1 Our role. For personal data whose purposes and means we determine (for example account, billing, marketing, security and product-improvement data), SemlyPro is a Data Fiduciary. Where an Indian business customer uses the Service to process the personal data of Data Principals, that customer is the Data Fiduciary and SemlyPro is a Data Processor acting under the DPA.
17.2 Notice and consent. For Indian Data Principals we provide a clear, itemised notice — separate from other terms — describing the personal data we process, the purposes, how to exercise your rights, and how to complain to the Data Protection Board of India. Our processing rests on your consent or on a “certain legitimate use” permitted by the DPDP Act (not on GDPR “legitimate interest”). You may withdraw your consent at any time, as easily as it was given, without affecting processing carried out before withdrawal. Where the DPDP Consent Manager framework becomes operational (registration provisions are expected to commence around November 2026), you will additionally be able to give and withdraw consent through a registered Consent Manager.
17.3 Your rights as a Data Principal. You have the right to:
- Access a summary of the personal data we process about you and the processing activities;
- Correction, completion, updating and erasure of your personal data;
- Grievance redressal — raise a grievance with us and receive a response within the prescribed period (see 17.4); and
- Nominate another individual to exercise your rights in the event of your death or incapacity.
17.4 Grievance Officer. Our India Grievance Officer is the readily-available point of contact for Data Principals’ questions and grievances about our processing:
India Grievance Officer — email: anil@semlypro.com. We will acknowledge grievances promptly and respond within the statutory timeline.
If your grievance is not resolved to your satisfaction, you may escalate to the Data Protection Board of India. This single Grievance Officer contact is also our published grievance/contact point for the purposes of the Consumer Protection (E-Commerce) Rules 2020 and the IT (Intermediary Guidelines) Rules 2021, each of which requires a published grievance officer for services offered to Indian users.
17.5 Children (under 18). Under the DPDP Act a child is anyone under 18. Before processing the personal data of a Data Principal who is a child, we require verifiable consent of a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. Our marketing site’s analytics and advertising features (see the Cookie Policy) are not directed at children; where India-facing traffic may involve a child, such features are suppressed or age-gated.
17.6 Breach notification. Our DPDP breach-notification obligations are set out in Section 11 (intimation to the Data Protection Board of India without delay, a detailed report within 72 hours, and direct notification to affected Data Principals in plain language).
17.7 Cross-border transfers. Under the DPDP Act, we may transfer Indian Data Principals’ personal data to any country other than those the Central Government of India restricts by notification. We monitor and will comply with any such restricted-country notifications and any sector-specific localisation directions, and we apply the technical and contractual safeguards described in Section 7 to those transfers.
17.8 Significant Data Fiduciary. If the Government of India designates us a Significant Data Fiduciary, we will appoint an India-based Data Protection Officer (answerable to us and serving as the grievance contact), appoint an independent data auditor, and conduct periodic Data Protection Impact Assessments and audits.
18. Contact
For any privacy-related question, request, or complaint:
- Privacy: anil@semlypro.com
- Security incidents: anil@semlypro.com
- Legal notices: anil@semlypro.com
- India grievances (Data Principals): anil@semlypro.com
- UK Article 27 representative: to be appointed and published (see Section 1.1)
- Postal address: Semly Pro (eenmanszaak, trading as SemlyPro), Hawaiiweg 41, 1339 NW Almere, Netherlands
Last updated 13 July 2026 · Operated by Semly Pro (eenmanszaak), KvK 99448351, Hawaiiweg 41, 1339 NW Almere, Netherlands · Questions about this document: anil@semlypro.com